• CONTACT
  • MARKETCAP
  • BLOG
Coin Mela Coin Mela
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Reading: Crypto Whale Loses $6 Million in Phishing Scheme Through Malicious Signature Approval
Share
  • bitcoinBitcoin(BTC)$90,795.00
  • ethereumEthereum(ETH)$3,113.98
  • tetherTether(USDT)$1.00
  • rippleXRP(XRP)$2.09
  • binancecoinBNB(BNB)$900.77
  • usd-coinUSDC(USDC)$1.00
  • solanaSolana(SOL)$134.78
  • tronTRON(TRX)$0.286379
  • staked-etherLido Staked Ether(STETH)$3,113.70
  • dogecoinDogecoin(DOGE)$0.141351
CoinMelaCoinMela
Font ResizerAa
  • Home
  • News
  • Learn
  • Market
  • Advertise
Search
  • Home
  • News
    • All News
    • Bitcoin
    • Ethereum
    • XRP
    • Altcoins
    • NFT
    • Blockchain
    • Web3
    • DeFi
    • Finance
    • Stocks
    • Company
  • Learn
  • Market
  • Advertise
Have an existing account? Sign In
Follow US
© Coin Mela Network. All Rights Reserved.
Ethereum

Crypto Whale Loses $6 Million in Phishing Scheme Through Malicious Signature Approval

News Desk
Last updated: September 18, 2025 10:24 pm
News Desk
Published: September 18, 2025
Share
crypto phishing

A significant incident in the crypto world has come to light, revealing the vulnerability of unsuspecting users to sophisticated phishing schemes. On September 18, a crypto whale suffered a staggering loss of over $6 million in staked Ethereum (stETH) and Aave-wrapped Bitcoin (aEthWBTC). According to blockchain security firm Scam Sniffer, the incident was a result of the victim unknowingly approving malicious signatures.

The attackers executed a well-crafted scheme, disguising their actions as a routine wallet confirmation process through what is known as “Permit” signatures. This manipulation tricked the victim into approving fund transfers without raising any red flags. Yu Xian, the founder of the blockchain security company SlowMist, commented on the matter, explaining that the victim did not perceive any threat due to the absence of gas fees associated with the transaction. He emphasized the ease of the attack, stating, “From the victim’s perspective, he just clicked a few times to confirm the wallet’s pop-up signature requests, didn’t spend a single penny of gas, and $6.28 million was gone.”

Permit approvals were originally intended to enhance user experience by simplifying token transfers. Instead of conducting on-chain approvals that incur fees, users can sign off-chain messages that authorize spending. However, this efficiency has inadvertently opened a new avenue for malicious actors. Once a user grants such a permit, attackers can exploit the combination of two functions—Permit and TransferFrom—to siphon assets directly from the user’s wallet. Because the authorization is executed off-chain, wallet dashboards remain unaffected until the transaction is finalized on-chain, by which point the tokens have already been rerouted to the attacker’s wallet.

The recent incident underscores a growing trend in the realm of phishing, with Scam Sniffer reporting that in August alone, attackers accumulated $12.17 million from over 15,200 victims. This marked a significant 72% increase in losses compared to July. Notably, the losses were concentrated among a few large accounts, with three accounts accounting for nearly half of the total damages. One particularly striking case involved a wallet that lost $3.08 million in a single exploit.

The surge in phishing losses has been attributed to the rise of EIP-7702 batch-signature scams and direct transfers to malicious contracts. In light of this alarming trend, security experts are urging cryptocurrency users to exercise extreme caution when interacting with wallet requests. It is essential to be wary of any demands for unlimited permissions to wallets, as these can pave the way for significant financial losses.

The incident serves as a stark reminder of the ever-present risks in the digital asset landscape, highlighting the need for heightened security measures and user awareness to combat increasingly sophisticated phishing attacks.

Cybersecurity Researchers Uncover Malware using Ethereum Smart Contracts on npm Registry
Ethereum Shows Bullish Signs as Whales Accumulate Over 1 Million ETH Amid Fed Rate Cut
Ethereum Foundation Launches dAI Team to Bridge Blockchain and AI Development
Defiance ETFs Files Applications for Bitcoin and Ethereum Market-Neutral ETFs
Stripe and Paradigm to Launch New Payment Platform Tempo, Echoing Libra Vision
Share This Article
Facebook Whatsapp Whatsapp
ByNews Desk
Follow:
CoinMela News Desk brings you the latest updates, insights, and in-depth coverage from the world of cryptocurrencies, blockchain, and digital finance.
Previous Article In the center the title Solana Dogecoin Remi… Dogecoin and Solana Gain Attention as Remittix Emerges as a Utility-Driven Altcoin
Next Article ER7CT5KIDRFZFNN5YRSPXQIJ3I RCMP Claims Largest Crypto Bust in Canadian History, Seizing $56 Million from TradeOgre
Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular News
urlhttps3A2F2Fg.foolcdn.com2Feditorial2Fimages2F8459222Ftrump addresses congress official w
Trump warns of economic disaster as Supreme Court prepares to rule on tariffs legality
GettyImages 1246498449
The Future of Crypto: From Speculation to Real Innovation
ba36666e23be4a688fb3c54f3af539b7
HBAR Price Declines 11% Amidst Continued Consolidation, Yet Investor Confidence Grows
- Advertisement -
Ad image

Follow Us on Socials

We use social media to react to breaking news, update supporters and share information

Twitter Youtube Telegram Linkedin
Coin Mela Coin Mela
CoinMela is your one-stop destination for everything Crypto, Web3, and DeFi news.
  • About Us
  • Contact Us
  • Corrections
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Advertise with Us
  • Quick Links
  • Finance
  • Company
  • Stocks
  • Bitcoin
  • News
  • XRP
  • Ethereum
  • Altcoins
  • Blockchain
  • DeFi
© Coin Mela Network. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?